-
A threat actor advertises a dataset of about 840,816 active WhatsApp accounts for Cyprus on a dark web forum, but the authenticity remains unverified.
-
The alleged data includes phone numbers, profile photos, gender, age, and other profile details with a file size of 9 GB.
-
Security analysts warn that such ‘WhatsApp databases’ often come from aggregated third-party sources rather than a direct compromise of WhatsApp’s infrastructure.

A dark web seller claims to have access to a large dataset of WhatsApp users from Cyprus. The listing says the information contains roughly 840,816 active accounts.
The seller posted a screenshot showing phone numbers and profile photos. It also displays gender, age, and other personal details. The advertised file size is about 9 GB, and the seller says they last updated the data on August 1.
The authenticity of this dataset remains unproven. No evidence shows the data came directly from WhatsApp’s systems. Security experts believe such databases often come from multiple sources.
Threat actors frequently compile information from OSINT, data enrichment services, and previous breaches. The claims of the seller therefore need independent verification.
What the Alleged Data Contains
The seller claims the dataset includes phone numbers and profile photos. It supposedly contains gender and age information for many users. Other profile-related attributes are also included in the package.
The screenshot shows records with phone numbers and account activation status. It also displays profile image types and gender details. Some entries even include hair color and inferred ethnicity. The seller provides these details to attract potential buyers.
Cyprus has about 152,321 users at risk according to previous WhatsApp data sales. Hence, this suggests that the dataset covers a considerable degree of WhatsApp users in Cyprus.
It is also noted that Cyprus is one of the countries in the world where instant messaging is one of the most commonly used online activities; over 96 percent of internet users engage with messaging platforms.
The listing appears to follow a pattern seen in previous dark web sales. Cybercriminals frequently advertise large datasets of user information. These often combine data from multiple sources rather than direct breaches.
How Such Data is Typically Compiled
As pointed out by security experts, ads like this have a common characteristic. Hackers always mention that they have access to many different sets of information about users.
They usually have data from a number of leaks, which means that the information may not be new. They may have collected with it OSINT, as well as through data enrichment services. Attackers also gather data from past leaks and scraped user profiles.
The sources of this data might be many, as sellers aggregate data over time. Thus, one large set of information may consist of several smaller ones. The mention that the date of the file is recent means the seller has recently compiled it. Having 9 GB of this file also suggests that this data is pretty big. This pattern fits with known cybercriminal behavior in personal information trading.
Similar claims have appeared on dark web forums in the past. A few years ago, a hacker advertised a database with 487 million WhatsApp user numbers; the dataset included information from 84 countries. Other recent listings have claimed to contain billions of WhatsApp-linked records. These often include full names, email addresses, and physical addresses.
The availability of such data has enabled attacks like the one Microsoft recently warned about, where Windows users are targeted through WhatsApp malware.
The dataset may not have come from WhatsApp’s servers at all. The infrastructure of the company has not been directly compromised in this case. However, data aggregation creates significant privacy risks.
Phone numbers paired with names and profile details can fuel various attacks. The dark web continues to host such trading activities despite law enforcement efforts.
Potential Risks and Precautions for Affected Users
If the dataset happens to be legitimate, the leaked details will carry some serious risks. The hackers could use the stolen numbers for phishing campaigns. They could also use texting for smishing attacks. Identity theft is a big issue for the affected individuals.
The criminals could also utilize this content to carry out social engineering schemes. They might combine it with information from other breaches. This creates more complete profiles for fraudulent activities.
Similar cyber threats occurred in Cyprus before, and the government is aware of the spyware attacks on WhatsApp users. The government provides guidance on safe digital practices. Users should monitor their accounts for suspicious activity.
Experts recommend that users stay vigilant against suspicious messages, they should never click links from unknown senders. They should also avoid sharing sensitive information through messaging apps.